A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
History

Wed, 20 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
CPEs cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Vendors & Products Moodle
Moodle moodle

Mon, 18 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
Title Moodle: some users can delete audiences of other reports
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-11-18T11:14:26.903Z

Updated: 2024-11-18T11:14:26.903Z

Reserved: 2024-10-09T12:15:07.577Z

Link: CVE-2024-48898

cve-icon Vulnrichment

Updated: 2024-11-18T14:56:06.172Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-18T12:15:18.363

Modified: 2024-11-20T14:46:16.237

Link: CVE-2024-48898

cve-icon Redhat

No data.